As per SP initiated SSO flow, User tries to access SP. Since the user is unauthenticated, he is redirected to IDP where he enters his credentials, post successful login, IDP sets cookies in user's browser(under IDP's domain) and redirects the user back to SP with SAML response. Once SP verifies SAML response it creates it's own cookie/token and sets in user's browser under sp's domain.
What should ideally happen in subsequent requests :
- Should SP rely only on it's own cookie to fetch user info
- Should SP validate user session with IDP in every request.
If option 1 is advised, Is it ok from security point of view as post login there is no communication between SP and IDP for further requests.
If option 2 is advised, there would be an overhead to call IDP in every request which might impact performance of the SP.
Please suggest what should be the ideal flow here.